Update of the TLS Certificate
In Q3 2026, Personio is updating the TLS certificate on our API endpoints from RSA 2048-bit to ECDSA P-256. For most integrations, no action is required.
Only those integrations that use certificate pinning or a custom CA trust store need a configuration change before the cutover. Because these settings live in your own systems, please forward this email to your development team that manages your Personio integration.
The certificates will be changed during our maintenance window on 22nd of September 2026.
What do I need to do next?
Please ask the team that manages Personio integration to verify the following configurations. These are deliberate configuration choices made when the integration was built, more common in environments with strict security requirements.
- Certificate pinning: If your integration pins against a leaf or intermediate TLS certificate, you will need to update your pin set before the cutover date. Pin to the public key of the Amazon root CAs instead.
- Custom trust stores: If you maintain your own CA bundle, ensure it includes all Amazon Trust Services root CAs before the cutover date. Standard OS and browser trust stores already include these roots and require no changes.
Key Changes
- Certificate algorithm changes from RSA 2048 to ECDSA P-256
- Issuing root CA will change from Amazon Root CA 1 to Amazon Root CA 3
- Cutover date: 22 September 2026
Frequently asked questions
Q: How do I know if my integration uses certificate pinning or a custom trust store?
A: These are deliberate configuration choices made when the integration was built, so the developer who built it is the fastest source of truth.
Q: Why is Personio making this change?
A: ECDSA P-256 certificates offer improved security and performance compared to RSA 2048-bit. This is consistent with current industry best practices.
If you need additional support, please contact us via your Partner Contact.
Best regards,
Your Personio Team

